Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
ISOL 533 ProjectOverviewWrite paper in sectionsUnderst.docx
1. ISOL 533 Project
Overview
Write paper in sections
Understand the company
Find similar situations
Research and apply possible solutions
Research and find other issues
Health network inc
You are an Information Technology (IT) intern
Health Network Inc.
Headquartered in Minneapolis, Minnesota
Two other locations
Portland Oregon
Arlington Virginia
Over 600 employees
$500 million USD annual revenue
Data centers
Each location is near a data center
Managed by a third party vendor
Production centers located at the data centers
Health network’s Three products
HNetExchange
Handles secure electronic medical messages between
Large customers such as hospitals and
Small customers such as clinics
2. HNetPay
Web Portal to support secure payments
Accepts various payment methods
HNetConnect
Allows customers to find Doctors
Contains profiles of doctors, clinics and patients
Health networks IT network
Three corporate data centers
Over 1000 data severs
650 corporate laptops
Other mobile devices
Management request
Current risk assessment outdated
Your assignment is to create a new one
Additional threats may be found during re-evaluation
No budget has been set on the project
Threats identified
Loss of company data due to hardware being removed from
production systems
Loss of company information on lost or stolen company-owned
assets, such as mobile devices and laptops
Loss of customers due to production outages caused by various
events, such as natural disasters, change management, unstable
software, and so on
Internet threats due to company products being accessible on
the Internet
Insider threats
Changes in regulatory landscape that may impact operations
4. Task 3: Risk Mitigation Plan
Project Part 2 Task 1: Business Impact Analysis (BIA) Plan
Task 2: Business Continuity Plan (BCP)
Task 3: Disaster Recovery Plan (DRP)
Task 4: Computer Incident Response Team (CIRT) Plan
Submission Requirements
All project submissions should follow this format:
ble
-point, double-space
Scenario
You are an information technology (IT) intern working for
Health Network, Inc. (Health Network), a fictitious health
services organization headquartered in Minneapolis, Minnesota.
Health Network has over 600 employees throughout the
organization and generates $500 million USD in annual
revenue. The company has two additional locations in Portland,
Oregon and Arlington, Virginia, which support a mix of
corporate operations. Each corporate facility is located near a
co-
6. and other medical facilities to allow Health Network
customers to find the right type of care at the right locations. It
contains doctors’ personal information, work addresses,
medical certifications, and types of services that the doctors and
clinics offer. Doctors are given credentials and are able
to update the information in their profile. Health Network
customers, which are the hospitals and clinics, connect to all
three of the company’s products using HTTPS connections.
Doctors and potential patients are able to make payments
and update their profiles using Internet-accessible HTTPS Web
sites.
Information Technology Infrastructure Overview
Health Network operates in three production data centers that
provide high availability across the company’s products.
The data centers host about 1,000 production servers, and
Health Network maintains 650 corporate laptops and
company-issued mobile devices for its employees.
Threats Identified
Upon review of the current risk management plan, the following
threats were identified:
production systems
-
7. owned assets, such as mobile devices and laptops
various events, such as natural disasters, change
management, unstable software, and so on
the Internet
r threats
Management Request
Senior management at Health Network has determined that the
existing risk management plan for the organization is out
of date and a new risk management plan must be developed.
Because of the importance of risk management to the
organization, senior management is committed to and supportive
of the project to develop a new plan. You have been
assigned to develop this new plan.
Additional threats other than those described previously may be
discovered when re-evaluating the current threat
landscape during the risk assessment phase.
The budget for this project has not been defined due to senior
management’s desire to react to any and all material risks
that are identified within the new plan. Given the company’s
10. www.jblearning.com Page 4
Project Part 1 Task 3: Risk Mitigation Plan
Senior management at Health Network allocated funds to
support a risk mitigation plan, and have requested that the risk
manager and team create a plan in response to the deliverables
produced within the earlier phases of the project. The risk
mitigation plan should address the identified threats described
in the scenario for this project, as well as any new threats
that may have been discovered during the risk assessment. You
have been assigned to develop this new plan using the
template provided in class.
Evaluation Criteria and Rubrics
-quality risk mitigation plan
based on material provided in the course?
parts of the project to build out a risk mitigation plan?
-developed draft
with proper grammar, spelling, and punctuation?
Project Part 2 Task 1: Business Impact Analysis (BIA) Plan
This part of the project is a continuation of Project Part 1 in
which you prepared an RA plan and a risk mitigation plan for
12. Company. All rights reserved.
www.jblearning.com Page 5
Project Part 2 Task 2: Business Continuity Plan (BCP)
After having reviewed and being impressed by your business
impact analysis (BIA), senior management at Health
Network has decided that your team must also develop a BCP.
Management has allocated all funds for a BCP and your
team has their full support, as well as permission to contact any
of them directly for participation or inclusion in your BCP
plan. You have been assigned to develop this new plan.
Winter storms on the East Coast have affected the ability of
Health Network employees to reach the Arlington offices in a
safe and timely manner. However, no BCP plan currently exists
to address corporate operations. The Arlington office is
the primary location for business units, such as Finance, Legal,
and Customer Support. Some of the corporate systems,
such as the payroll and accounting applications, are located
only in the corporate offices. Each corporate location is able
to access the other two, and remote virtual private network
(VPN) exist between each Production data center and the
corporate locations.
13. The corporate systems are not currently being backed up and
should be addressed in the new plan. The BCP should also
include some details regarding how the BCP will be tested.
You may refer to the following additional resources to help you
and your team develop a BCP, and you may use a BCP
template if found during your research.
References:
Questions (Protiviti, 2013),
http://www.protiviti.com/en-US/Documents/Resource-
Guides/Guide-to-BCM-Third-Edition-Protiviti.pdf
.gov),
http://www.ready.gov/business/implementation/continuity
Evaluation Criteria and Rubrics
operations while efforts are ongoing to restart
pervious operations?
tely fill out a BCP template if found
during their research?
presented in class?
15. operations while efforts are ongoing to restart
pervious operations?
research?
presented in class?
-developed report
with proper grammar, spelling, and punctuation?
Project Part 2 Task 4: Computer Incident Response Team
(CIRT) Plan
By now you should have developed an RA, a risk mitigation
plan, and a BIA, BCP, and DRP.
In this part of the project, you will create a CIRT plan for
Health Network. The company headquarters (HQ) handles all
incidents because the information security organization is
located in Minneapolis, so the plan will have its roots at HQ.
Make sure to incorporate your instructor’s feedback on earlier
submissions if applicable to the CIRT plan.
Evaluation Criteria and Rubrics